Splunk Search

Why is data summary not displaying?

akankshayadav
Path Finder

When I am click on my data summary, it is not displaying anything just showing

akankshayadav_0-1625829593402.png

Any suggestions?
Thanks.

Labels (1)
0 Karma

aliazaad
New Member

if you select index=main for your input 

the problem will be solved

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @akankshayadav,

I haven't your issue in my Splunk, which version are you using?

My only hint is to open a Case To Splunk Support.

Ciao and Happy Easter.

Giuseppe

0 Karma

state_larson_ti
Path Finder

Actually a little more searching and I found the answer here (https://community.splunk.com/t5/Knowledge-Management/How-to-fix-misleading-quot-What-to-search-quot-...). I also on my experimental/learning box (latest version) had enabled (under Settings -> Roles -> Admin -> Indexes) the * (All non-internal indexes) and the _* (All internal indexes) to be default and this immediately allowed data summary to work and see all the indexes.  I can see how, by default, you might not want to have this enabled for the admin account.

I think in courses you do, they may enable this by default for your accounts on non-internal indexes to make it easier for you to configure things, so I had not had to configure it myself.

0 Karma

state_larson_ti
Path Finder

Good Day.  I was curious if you had ever found an answer here.  I noticed the same thing, logged in about 3 days later, and the data had been populated (but not for the data I had put in the day before.  I assume there is a search that populates this data, but it only runs maybe 1/x per day or week.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...